Description
SailPoint is excited to announce that Inactive (long-term) identities will be excluded from the attribute sync process! This enhancement is available in all sandbox tenants. It will begin rolling out to production tenants on October 7, 2024.
This enhancement was a top request following the initial release of New Capability: Management of Inactive Identities. Administrators will have more control over the the last update to leavers’ accounts, and see a reduction in unneeded provisioning load.
Problem
Attribute syncs to inactive identities’ accounts are unneeded in most cases. The extra traffic can cause infrastructure problems and interfere with leaver processes. 51 voters have asked us to solve this problem in this idea.
Solution
Inactive (long-term) identities will be excluded from the attribute sync process except when:
- The identity just became inactive (long-term). In this scenario, the system provisions one last sync to handle for OU moves, deletions, etc. specified in a Before Provisioning rule.
- The administrator requests it via the Synchronize Attributes action. Synchronize Attributes can also be called via /beta/identities/:identityId/synchronize-attributes.
What’s the updated view of how the three identity states are used?
Active
identities will be included in all services. Inactive (short-term)
will be excluded from some services. Inactive (long-term)
will be excluded from most services.
Area | Active | Inactive (short-term) | Inactive (long-term) |
---|---|---|---|
Identity Picklists in Request Center | ![]() |
![]() |
![]() |
My Team UI for Managers | ![]() |
![]() |
![]() |
Scheduled Processing | ![]() |
![]() |
![]() |
Apply Changes on Roles, Access Profiles, and Apps UIs | ![]() |
![]() |
![]() |
Attribute Sync | ![]() |
![]() |
![]() |
Apply Changes on Identity Profiles UI | ![]() |
![]() |
![]() |
Processing for Select Identities | ![]() |
![]() |
![]() |
Identity Attribution Promotion after Accounts Updated in Aggregations | ![]() |
![]() |
![]() |
What if I need to sync attributes for recent leavers?
You might require a recent leaver lifecycle state in addition to a long-term leaver lifecycle state if you need to sync attributes for recent leavers. For example, it’s common to see a two-stage termination step with lifecycle states named Terminated < 90 days
and Terminated < 90 days
. Identities in Terminated < 90 days
would receive syncs because their lifecycle state is marked Inactive (short-term)
. Identities in Terminated > 90 days
would not receive syncs because their lifecycle state is marked Inactive (long-term)
. Hold identities in the first-stage lifecycle state as long as you’re required to sync attributes.
Lifecycle states | |
---|---|
Pre-Hire | Active |
Active | Active |
Leave of Absence | Active |
Terminated < 90 days | Inactive (short-term) |
Terminated < 90 days | Inactive (long-term) |
What if I need to sync attributes for long-term leavers?
To continue the previous example, you might need to sync attributes for identities in the second-stage lifecycle state (Terminated < 90 days
). In this scenario, the administrator can use the Synchronize Attributes action. Synchronize Attributes can also be called via /beta/identities/:identityId/synchronize-attributes.
Will attributes sync when an identity just became a long-term leaver?
The system will complete one last attribute sync when an identity enters a lifecycle state that is configured as Inactive (long-term)
. This covers most use cases concerning OU moves, deletions, etc. specified in a Before Provisioning rule.
Who is affected?
All customers who have implemented both identity states and attribute sync.
Action Required
Review and implement the Identity States feature if you haven’t yet. The Identity States feature enables you to mark identities as inactive to exclude them from access requests, manager views, and more. This enhancement adds one more reason to enable the Identity State feature. A guide to enable the feature is available here: New Capability: Management of Inactive Identities.
Important Dates
- Sandbox: Monday, September 30th
- Production: The week of Monday, October 7th